AI Network Security Protection for Encrypted Traffic Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions struggle to effectively identify and clean encrypted attack traffic, particularly in HTTPS protocols, due to high resource consumption and limitations in content detection technologies.

Innovation Solution

An AI-based network security protection method and apparatus that utilizes a neural network model to classify sessions as normal or abnormal based on data statistical features, allowing for the identification and cleaning of both encrypted and unencrypted attack traffic without decryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If content detection technology is used to identify attack traffic in HTTPS protocol, then identification accuracy is improved, but resource consumption increases and effectiveness decreases due to encryption

Engineering Contradiction:
Improveattack traffic identification accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts statistical features from encrypted HTTPS traffic without requiring decryption. By taking out and analyzing only the metadata and statistical characteristics (packet length, frequency, timing patterns) while leaving the encrypted content intact, the system achieves effective attack traffic identification without the high resource consumption associated with decryption and content inspection

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces statistical feature analysis as an intermediary approach between raw encrypted traffic and attack identification. Instead of directly inspecting encrypted content (which requires decryption) or using simple packet filtering (which lacks accuracy), the system uses statistical features as a mediator that preserves identification effectiveness while avoiding the resource-intensive decryption process

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If HTTPS protocol is used for secure data transmission, then information confidentiality is improved, but attack detection capability deteriorates due to encryption

Engineering Contradiction:
Improveinformation confidentialityVSAvoidattack traffic detection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent shifts the detection dimension from content-based analysis (which is blocked by encryption) to statistical feature-based analysis. By moving to another dimension of traffic characterization—analyzing packet length distributions, timing patterns, and frequency characteristics instead of inspecting encrypted payloads—the system maintains attack detection capability while preserving HTTPS confidentiality

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If traditional content detection methods are used on encrypted traffic, then identification thoroughness is improved, but processing speed and efficiency deteriorate

Engineering Contradiction:
Improvetraffic identification thoroughnessVSAvoidtraffic processing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts only the necessary statistical features from traffic flows, avoiding the computationally expensive process of full content inspection. By taking out and analyzing only metadata characteristics (packet sizes, intervals, frequencies) rather than processing entire encrypted payloads, the system maintains identification thoroughness while achieving high processing speeds that can keep pace with encrypted traffic flows

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12316658B2Artificial intelligence-based network security protection method and apparatus, and electronic device
Publication Date: 2025.05.27 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US12316658B2 patent drawing
  • US12316658B2 patent drawing
  • US12316658B2 patent drawing

AI summary

This application provides an artificial intelligence (AI)-based network security protection method and apparatus, an electronic device, and a computer-readable storage medium. The method includes obtaining access traffic that needs to be verified and to be transmitted to a target network address; extracting a data statistical feature of each of a plurality of sessions included in the access traffic that needs to be verified; invoking a neural network model, and based on the data statistical feature of each session, to classify each session as normal or abnormal; identifying a session classified as abnormal in the access traffic that needs to be verified as attack access traffic; and obtaining a source address of the attack access traffic, and screening attack access traffic to be transmitted to the target network address from the source address.